
Llavero.io Security & Risk Analysis
wordpress.org/plugins/llavero-ioEste plugin permite vincular las cuentas de usuario de WordPress con Llavero.io para tener un segundo factor de authenticación (2FA) en el login de lo …
Is Llavero.io Safe to Use in 2026?
Generally Safe
Score 85/100Llavero.io has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'llavero-io' plugin exhibits several security concerns despite a clean vulnerability history. The static analysis reveals a significant attack surface with 10 AJAX handlers, of which 8 lack authentication checks. This is a critical vulnerability, as it allows unauthenticated users to interact with potentially sensitive plugin functionalities. Furthermore, all 4 SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities, especially in conjunction with the unprotected AJAX endpoints. Taint analysis indicates 2 high-severity flows, suggesting potential for data manipulation or unauthorized access, although their exact nature is not detailed here. The absence of nonce checks on AJAX endpoints further exacerbates the risk of Cross-Site Request Forgery (CSRF) attacks. While the plugin has no recorded vulnerabilities, this should not be interpreted as a sign of robust security, given the identified weaknesses in the code itself. The high percentage of properly escaped outputs (84%) and the absence of dangerous functions or file operations are positive signs. However, the numerous unprotected entry points and the reliance on raw SQL queries pose a substantial risk that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Raw SQL queries without prepared statements
- High severity taint flows
- Missing nonce checks on AJAX
Llavero.io Security Vulnerabilities
Llavero.io Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Llavero.io Attack Surface
AJAX Handlers 10
WordPress Hooks 10
Maintenance & Trust
Llavero.io Maintenance & Trust
Maintenance Signals
Community Trust
Llavero.io Alternatives
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
PassClip Auth for WordPress
passclip-auth-for-wordpress
"PassClip Auth" provides strong and easy authentication. "PassClip Auth for WordPress" is the plugin to launch PassClip Auth to Wo …
4Login for Secure And Smart Access
4login-for-secure-and-smart-access
4Login will give you an easy and powerful authentication (connect to an external server for authentication).
AV 2FA
av-2fa
A simple and secure Two-Factor Authentication plugin that sends a verification code to your email.
DB Solution – 2FA
db-solution-2fa
Advanced security module for the DB Solution suite. Adds email-based 2FA, Strict Mode protection, and hides the standard login URL.
Llavero.io Developer Profile
1 plugin · 10 total installs
How We Detect Llavero.io
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/llavero-io/includes/js/cilib.jshttps://unpkg.com/node-forge@0.7.0/dist/forge.min.js/wp-content/plugins/llavero-io/includes/js/cilib.jsHTML / DOM Fingerprints
id="cill_messages"id="cill_appid"id="ciberllaverouserkey"id="ciberllavelogin_user"id="ciberllavelogin_password"name="empezarcill"+4 morewindow.cilib